Apparatus and method for context-based message traffic obfuscation
By receiving context attributes from the processor, selecting the security context, and generating flow control instructions, the message flow of IoT devices is coordinated, solving the problem of excessive resource consumption in existing technologies and achieving efficient side-channel protection.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- HUAWEI TECH CO LTD
- Filing Date
- 2019-10-17
- Publication Date
- 2026-04-21
AI Technical Summary
Existing technologies consume too many resources when preventing side-channel attacks and cannot efficiently protect the network communication security of IoT devices.
The processor receives context attributes, selects a security context, and generates flow control instructions to coordinate message traffic from IoT devices, including suppressing, replaying, or generating noisy messages to confuse attackers while optimizing resource usage.
It effectively prevents side-channel attacks, reduces power and network bandwidth consumption, and improves the security and resource utilization efficiency of IoT devices.
Smart Images

Figure CN114556995B_ABST
Abstract
Description
Technical Field
[0001] The various aspects of the disclosed embodiments generally relate to computer security systems, and more specifically, to protecting computer network communications. Background Technology
[0002] Modern network-based information systems, such as security systems and health or medical monitoring applications, rely on the Internet of Things (IoT) to collect the information necessary to perform their intended tasks. A growing number of IoT devices, including motion detectors, temperature sensors and monitors, and communication equipment, can collect a wide variety of information. The increasing quantity and type of data generated by IoT devices and transmitted through digital networks have led to the emergence of many new attack vectors, all of which require protection.
[0003] Most traditional network-based systems employ encryption to protect transmitted data. However, a significant amount of information can still be inferred from the metadata associated with network message traffic. This metadata can include the size, frequency, source, destination, and even presentation information of the messages transmitted by these IoT devices. For example, when a motion detector remains silent for an extended period and then suddenly transmits a message, an attacker can infer that the IoT device detected motion. When data is transmitted to a terminal belonging to a company that manufactures motion detection and sensing equipment, information about users within the area can be inferred. These types of security attacks are known as side-channel attacks.
[0004] Traditional solutions include programming IoT devices to transmit continuous message streams to prevent simple side-channel attacks. However, this approach wastes valuable resources such as device power, network bandwidth, and other system resources to transmit these noisy messages.
[0005] Therefore, an improved method and apparatus are needed to prevent side-channel attacks in a more resource-efficient manner. Accordingly, it is desirable to provide a method and apparatus that at least partially solves the above-mentioned problems. Summary of the Invention
[0006] The purpose of the disclosed embodiments is to provide an improved method and apparatus that provides effective side-channel protection while minimizing resource consumption. The subject matter of the independent claims is to achieve this objective. Further advantageous modifications can be found in the appended claims.
[0007] According to the first aspect, the above and other objects and advantages are achieved by means including a processor coupled to a memory. The processor is configured to: receive at least one context attribute, wherein the at least one context attribute includes one or more of the following: system and environment attributes, user input, device information, and sensing information; select a security context based on the received at least one context attribute; determine a protection action based on the selected security context; and determine one or more flow controls based on the determined protection action and the at least one context attribute. The processor sends the one or more flow controls to one or more IoT devices. The one or more flow controls are used to cause the one or more IoT devices to perform the protection action.
[0008] In a first possible implementation of the device, the security context includes one of the following: a privacy protection context, a hidden selected activity context, an intrusion mitigation context, and a risk-free context. Using various security contexts, the system state can be categorized into security contexts that indicate different system objectives.
[0009] In one possible implementation of the device, the processor is configured to select the privacy protection context when one or more persons are within a protected area and the time is within a predefined time range. The selection of the privacy protection context indicates a specific protective action that is beneficial to protecting the privacy of the system's region of interest.
[0010] In one possible implementation of the device, the processor is configured to select the context for concealing the selected activity when security personnel are on duty and the time falls within a predefined patrol period. Concealing the selected activity can be advantageous in many situations, such as concealing the movement of security personnel.
[0011] In one possible implementation of the device, the protection actions include one or more of the following: completely suppressing the generation of message traffic, generating obfuscated noise message traffic, replaying recorded message traffic, and replaying predefined message traffic. Using multiple protection actions allows the device to adjust system behavior for various different objectives and states.
[0012] In one possible implementation of the device, one or more flow control mechanisms are used to cause a first IoT device to generate a first noisy flow pattern and a second IoT device to generate a second noisy flow pattern; wherein the first and second noisy flow patterns are time-shifted. Coordinating flow patterns among multiple IoT devices provides additional flexibility and can be used to effectively confuse attackers while minimizing the use of system resources.
[0013] In one possible implementation of the device, when the selected security context is the hidden activity context, the one or more flow control measures are used to suppress message traffic in one or more of the one or more IoT devices. Complete suppression of message traffic prevents side-channel attackers from detecting events such as intruder detection or security personnel movement.
[0014] In one possible implementation of the device, the one or more flow control mechanisms are used to generate randomly spaced noise signals from two or more IoT devices. The advantage of coordinating randomly spaced signals from multiple IoT devices is that it can confuse an attacker using significantly fewer resources. For example, sending sporadic messages from several devices at a relatively low frequency produces the same level of confusion as sending frequent noise messages from all devices.
[0015] In one possible implementation of the device, the device information includes power information, and the processor is configured to adjust one or more flow control measures based on the power information. The power information includes information relating to the power capabilities of at least one of the one or more IoT devices. Power information is included in the device information.
[0016] In one possible implementation of the device, the processor is configured to determine one or more flow control measures based on network bandwidth. Saving network bandwidth can significantly reduce costs.
[0017] In one possible implementation of the device, the processor is configured to determine one or more flow control measures based on a maximum reporting rate, wherein the maximum reporting rate is dynamically determined based on a determined minimum amount of noise traffic and the maximum transmission rate of the one or more IoT devices. This allows flow control to be adjusted in a way that optimizes network usage.
[0018] In one possible implementation of the device, the flow control includes one or more of the following: the data packet to be replayed, the script to be replayed, the random data packet size, the transmission frequency, the session length, the maximum data volume, and the stopping condition. Providing multiple options for generating message traffic allows for more efficient system optimization.
[0019] According to the second aspect, the above and other objectives and advantages are achieved through a method. The method includes receiving at least one context attribute, wherein the received at least one context attribute includes one or more of the following: system and environment attributes, user input, device information, and sensing information. Based on the received at least one context attribute, a security context is selected; based on the selected security context, a protection action is determined; based on the determined protection action and the at least one context attribute, one or more flow controls are determined. The method sends the flow controls to one or more IoT devices, wherein the one or more flow controls are used to cause the one or more IoT devices to perform the protection action.
[0020] In a first possible implementation of the method, the security context includes one of the following: a privacy-preserving context, a hidden-selection-activity context, an intrusion mitigation context, and a risk-free context. Using various security contexts, the system state can be categorized into security contexts that indicate different system objectives.
[0021] According to the third aspect, the above and other objects and advantages are obtained by a computer program product comprising non-transitory computer program instructions that, when executed by a processor, cause the processor to perform the method provided in the second aspect.
[0022] These and other aspects, implementations, and advantages of the exemplary embodiments will be apparent from the embodiments described in conjunction with the accompanying drawings. However, it should be understood that such descriptions and drawings are for illustrative purposes only and should not be construed as limiting the invention; any limitation on the invention should be referenced to the appended claims. Other aspects and advantages of the invention will be set forth in the following description, and some aspects and advantages will be apparent from the description or may be learned by practicing the invention. Furthermore, aspects and advantages of the invention may also be realized and obtained by the means or combinations particularly pointed out in the appended claims. Attached Figure Description
[0023] In the following detailed description of the invention, the invention will be explained in more detail with reference to exemplary embodiments shown in the accompanying drawings, wherein:
[0024] Figure 1 A block diagram of a computing system incorporating aspects of the disclosed embodiments is shown, the computing system being used to prevent side-channel attacks using context-based traffic obfuscation;
[0025] Figure 2 A coordinate graph showing exemplary message traffic that an IoT device can transmit in conjunction with various aspects of the disclosed embodiments is shown;
[0026] Figure 3 A coordinate graph illustrating how side-channel protection can be applied in a system with multiple IoT devices, incorporating aspects of the disclosed embodiments;
[0027] Figure 4 A coordinate graph is shown illustrating a novel method for preventing side-channel attacks incorporating various aspects of the disclosed embodiments;
[0028] Figure 5 A flowchart is shown illustrating an exemplary method for implementing context-based fuzzing techniques incorporating aspects of the disclosed embodiments. Detailed Implementation
[0029] refer to Figure 1 The diagram shows a block diagram of a networked computing system 100 incorporating various aspects of the disclosed embodiments, which is used to prevent side-channel attacks using context-based traffic obfuscation. The system 100 includes a computing device 102 communicatively coupled to one or more sensing devices 114 (referred to herein as IoT devices), wherein the computing device 102 is configured to provide improved security by coordinating the generation of message traffic 136 sent by the IoT devices 114, preventing attackers with access to the generated message traffic 136 from obtaining useful information through side-channel attacks.
[0030] refer to Figure 1 In one embodiment, device 102 includes a processor 150 coupled to memory 152, wherein the processor 150 is configured to receive at least one context attribute, wherein the at least one context attribute includes one or more of the following: system and environment attributes 122, user input 124, device information 108, and sensing information 130. Based on the received at least one context attribute, a security context 132 is selected. Based on the selected security context 132, a protection action is determined. Based on the determined protection action and the at least one context attribute, one or more flow controls 134 are determined. One or more flow controls 134 are sent to the one or more IoT devices 114; wherein the one or more flow controls 134 are used to cause the one or more IoT devices 114 to perform the protection action.
[0031] Many modern computing devices, such as the computing device 102, interact with various devices (e.g., the one or more devices 114) using wide area networks such as the Internet. This group of devices (including the one or more IoT devices 114), the networks they are connected to, and the various computing devices also connected to the networks are commonly referred to as the Internet of Things (IoT). As used herein, the term "IoT device" refers to any device that can be incorporated into the various networked devices in the Internet of Things. IoT devices can be used to provide a variety of information and achieve many different purposes. For example, the IoT device 114 may include cameras, audio and communication devices, motion detectors, door and window sensors, medical monitoring devices, light switches or other electrical switching devices, cloud-based software services, home appliances, and online data and software services, etc.
[0032] The computing device 102 may be any suitable type of computing device for processing and storing data and communicating with other digital devices via computer-based networks such as the Internet. The computing device 102 includes a processor 150 communicatively coupled to a computer memory or memory 152, and the processor 150 is used to read and execute non-transitory program instructions stored in the memory 152.
[0033] The processor 150 may be a single processing device or may include multiple processing devices, such as dedicated devices, digital signal processing (DSP) devices, microprocessors, dedicated processing devices, parallel processing cores, or general-purpose computer processors. In some embodiments, the computing device may be combined with a cloud-based computing device. In one embodiment, the processor 150 may include a central processing unit (CPU) that works in conjunction with a graphics processing unit (GPU), wherein the GPU may include a DSP or other dedicated graphics processing hardware. The processor 150 is used to read non-transitory program instructions from the memory 152 and execute embodiments of the methods and processes disclosed herein.
[0034] The memory 152 may be any suitable type of computer memory capable of storing and retrieving computer program instructions and / or data. The memory 152 may be a combination of various types of volatile and non-volatile computer memory, such as read-only memory (ROM), random access memory (RAM), magnetic disk or optical disk, or other types of computer-operable memory capable of storing and retrieving computer program instructions and other types of data.
[0035] The computing device 102 is used to receive various inputs, data, or information that are meaningful for security or other system 100 objectives. Hereinafter, these different inputs are collectively referred to as context attributes. The context attributes may include any information that helps determine the context or security context of the system 100, including: environmental conditions, activity patterns related to privacy or security topics, user inputs and preferences 124, sensing parameters 136 (e.g., those obtained from IoT devices 114), and activity patterns. The context attributes may also include inputs from external systems 122 such as user personal devices, cloud services, internet knowledge bases, public alarm systems, etc. In some embodiments, it may also be advantageous to include information 108 related to the one or more IoT devices 114 in the context attributes, such as metadata such as the network capabilities, power requirements, and available resources of each IoT device 114, and the type of each IoT device 114.
[0036] The exemplary computing device 102 selects a security context 132 based on the received context attributes. The security context 132 represents a set of context attributes, environmental conditions, activity patterns, and user input related to security or system objectives. For example, the activity patterns may be related to activities on security or privacy topics of interest to people in the home or pets.
[0037] Some exemplary security contexts 132 may include privacy protection contexts, the purpose of which is to protect the privacy of users such as homeowners, guests, or security personnel. In such privacy protection contexts, it may be desirable to hide information about a user's location and / or movement, for example, when a special or important guest visits. Privacy protection contexts or private scenario protection contexts may be defined in the form of one or more conditions, such as when someone is home and the time is during bedtime, between 10 p.m. and 7 a.m., or when the door is locked and the curtains are closed.
[0038] Appropriate protective actions can be configured to be applied during the privacy protection context, such that when an IoT device 138 is detected moving in a specific room, other IoT devices 114 located in different rooms of the home can replay the original notification using some randomization mechanism. This can confuse attackers by hiding the user's location in the middle of the additional noise transmission.
[0039] Exemplary security context 132 may include an invisible primary context. An invisible primary context can be applied to instruct patrolling security personnel within a monitored area to remain invisible while patrolling. An invisible primary context can be selected, for example, when security personnel are on duty and the time is between 10 PM and 7 AM, or during patrol periods such as holidays. Possible protective actions that can be applied when an invisible primary context is active could be: when IoT device 138 identifies a security personnel on duty, instructing other IoT devices 114 (e.g., motion detectors and other sensors located in the same area as the on-duty security personnel) to suppress message transmission. Once the on-duty security personnel move to another location, these suppressed IoT devices 114 switch back to active mode.
[0040] Advantageously, security contexts can be: risk-free contexts, applied during public events where no information needs to be protected because all information is publicly available during this period; privacy-protecting contexts, which require scrambling or hiding movement or interaction between people; selected activity-hiding contexts, which require suppressing reports about selected people, roles, etc., and hiding their movement; and intrusion mitigation contexts, which require scrambling all message traffic or suppressing all reports when anomalies are detected.
[0041] In one embodiment, the selection of the security context 132 is performed by a context manager 104 included in the computing device 102. The context manager 104 can be used to determine or select a suitable security context 132 based on the received context attributes. The selection of the security context 132 can be performed in any suitable manner, such as by a set of if-then-else rules processed by an inference engine, classification techniques, machine learning algorithms, or deep neural networks. Once the security context 132 is selected, the computing device 102 can use the selected security context 132 to determine subsequent actions.
[0042] In the exemplary computing device 102, appropriate protection actions and appropriate flow control are identified or determined within the flow coordinator 106. The flow coordinator 106 may also be referred to as a security coordinator, depending on the desired objectives of the system 100. In some embodiments, it may be advantageous to adjust the protection actions based on the functionality of the IoT devices 114, network capabilities, available resources, and how the protection actions consume them. Flow control 134 is generated by the flow coordinator 106 and sent to one or more IoT devices 114. As used herein, the term "flow control" 134 refers to one or more flow generation commands or instructions used to cause the one or more IoT devices 114 to generate message traffic consistent with the objectives of the system 100, as indicated by the selected security context 132. A set of computer messages or data signals sent between computing devices or IoT devices connected by a computer network is collectively referred to as message traffic.
[0043] Within each IoT device 114, an optimal or best protection action can be selected for activation. The optimal or best protection action can be an action that satisfies certain security objectives while minimizing the use of system 100 resources. For example, during a power outage, the flow coordinator 106 may preferentially generate message traffic or noise from self-powered IoT devices 114, rather than selecting IoT devices 114 that require grid power. Conversely, when grid power is restored, the flow coordinator may preferentially use IoT devices 114 directly connected to the grid to protect the battery life of stand-alone or autonomous devices.
[0044] Various protective actions can be advantageously employed within the system 100. One useful protective action is to completely suppress message traffic, i.e., instruct one or more IoT devices 114 to suppress the transmission of any messages. Message suppression prevents the IoT devices 140 from sending any messages. This can be achieved by discarding the messages or by reserving them for later transmission. Suppression is very useful when it is necessary to hide messages from attackers.
[0045] The protection action may include replaying recorded message traffic. Replaying recorded message traffic is a way to simulate actual messages and also provides an opportunity to send misleading information to attackers. As a way to confuse attackers, the recorded message traffic can be replayed at a later time.
[0046] In one embodiment, the protective action may include playing predefined message traffic. In some embodiments, the predefined message traffic may be designed to simulate actual or real traffic patterns and include accidental deviations. The use of predefined message traffic provides a means of injecting carefully crafted traffic patterns to confuse or mislead attackers.
[0047] Protection actions may include generating obfuscated noise message patterns. These obfuscated noise message patterns require dynamic adjustment to optimally serve a given situation or context, where such dynamic adjustment may include randomness. Dynamic adjustment achieves desired system objectives by modifying the message patterns, while also optimizing the use of system resources.
[0048] The traffic coordinator 106 can coordinate subsequent actions within the system 100, such as noise injection or traffic suppression. The traffic coordinator is used to coordinate traffic generated by one or more IoT devices 114 in response to triggers provided by the context manager 104. In one embodiment, when coordinating subsequent actions within the system 100, the traffic coordinator 106 may also consider other information, such as sensor information 136, device data 108, or any other appropriate information.
[0049] In addition to other tasks, the flow coordinator 106 is also responsible for selecting which IoT devices 114 to use to generate noise. This selection is based on the capabilities of each IoT device 114. For example, if two or more IoT devices 114 can generate similar noise, the flow coordinator 106 may select IoT devices 114 directly connected to mains power and avoid selecting IoT devices 114 with limited available battery power. In this sense, the term "similar noise" refers to noise that achieves the same system 100 objective.
[0050] The flow control 134 within a computing device, such as computing device 102, can coordinate the generation and transmission of message traffic from multiple IoT devices 114. While optimizing the use of system 100 resources, this coordination can be advantageously applied to effectively confuse attackers. For example, flow control 134 can be configured to transmit noise from similar IoT devices (e.g., motion detectors located in different rooms) with random offsets, thereby hiding any real messages within random spatial noise messages. Coordinating the transmission of noise from multiple IoT devices can effectively confuse attackers while using significantly fewer resources than conventional techniques. To advantageously achieve the aforementioned protective actions, the flow control 134 can be configured by flow coordinator 106 to coordinate the message traffic transmitted by the multiple IoT devices 114.
[0051] In the system 100, at least one of the IoT devices 114 includes a traffic generator 118. The traffic generator 118 is a system component for receiving flow control 134 and adjusting the message traffic 136 transmitted by the IoT devices 114 according to the received flow control 134. The flow control 134 or instructions processed by the traffic generator 118 include instructions or indications defining noisy traffic parameters, such as: network packets to be replayed, scripts to be replayed, instructions to generate random packet sizes, transmission frequency of transmitted message traffic, session length, maximum data size, stop conditions, or any other desired traffic-related parameters.
[0052] In some embodiments, it is advantageous to process the sensing information 136 received from the IoT device 114 to generate context-specific sensing inputs 130. These context-specific sensing inputs 130 can be tailored to the needs of the currently selected security context 132, or more broadly tailored to suit all security contexts according to the needs of the traffic manager 104. The communication system 110 may be included in the computing device 102 to receive the sensing inputs 136 from the IoT device 114 and generate context-related sensing inputs 130.
[0053] Figure 2 Coordinate graphs 200 and 210 illustrate exemplary message traffic that an IoT device can transmit. Coordinate graphs 200 and 210 represent time along a horizontal axis 204 that increases to the right, and message traffic along a vertical axis 202. Transmitted messages are depicted as rectangles 206 and 208, projected upwards from a baseline 212, with each rectangle representing a transmitted message.
[0054] Coordinate diagram 200 illustrates the transmission of a single message 206 that can be sent by an IoT device in response to a trigger. For example, a motion detector might send message 206 after being triggered by someone entering the room, or a door sensor might send message 206 when the door is opened. The message 206 may include data describing a specific event and providing detailed information about that event. The privacy of the data contained in each message 206 is typically protected by cryptography or other appropriate means to prevent an attacker from accessing any of the data contained in the message 206. However, even without access to the data contained in the message 206, an experienced attacker can still obtain useful information. For example, the presentation of message 206 and the available metadata can provide valuable information to an attacker. The message 206 could reveal to an attacker that someone is home, or it could simply be used to track the movement of people in the home by monitoring which IoT devices are sending messages. In this document, these types of attacks are referred to as side-channel attacks.
[0055] Coordinate graph 210 illustrates a conventional method for preventing side-channel attacks. Coordinate graph 210 shows the message traffic transmitted by an IoT device that periodically transmits a simulated signal 208. In this document, the simulated signal 208 is referred to as noise 208. The noise 208 is configured to be identical to the actual message 206 from the perspective of a side-channel attack and can only be distinguished after accessing data content that is not available to the attacker as described above. Therefore, the attacker cannot distinguish between the real message 206 and the added noise 208.
[0056] As shown in coordinate graph 210, periodic or recurring noise injection can consume significant system resources. Battery-powered IoT devices can deplete power more quickly, and the increased noise 208 consumes network bandwidth, thus limiting side-channel protection and increasing operating costs.
[0057] Figure 3 Coordinate diagrams S1a, S2a, and S3a illustrate how side-channel protection can be applied in a system with multiple IoT devices. Coordinate diagrams S1a, S2a, and S3a use the same nomenclature as those used in coordinate diagrams 200 and 210 to describe the message traffic transmitted by the IoT devices. Coordinate diagrams S1a, S2a, and S3a show how the side-channel protection method described above, shown in coordinate diagram 210, can be applied in a system with three IoT devices. When an IoT device is triggered, message 306 providing information related to the triggering event is transmitted. As described above, the regular noise message 308 transmitted by the active IoT device conceals message 306. To further confuse attackers, other IoT devices can transmit noise messages 310 and 312. This side-channel protection method can be implemented without coordination between the IoT devices. The noise messages 308, 310, and 312 are used to confuse attackers but increase power and network usage as well as other system resources.
[0058] Figure 4 Coordinate diagrams S1b, S2b, and S3b are shown, illustrating a novel method for preventing side-channel attacks incorporating aspects of the disclosed embodiments. The coordinate diagrams S1b, S2b, and S3b utilize... Figure 3 The same naming convention is used, and coordinate graphs S1b, S2b, and S3b represent messages transmitted by one of the three IoT devices (not shown). In this paper, this method is referred to as context-based traffic obfuscation, used to generate messages that can provide similar functionality to the aforementioned traditional noise generation schemes. Figure 2 and Figure 3Similar side-channel protection, but this approach is more efficient from the perspectives of power consumption, performance, and system resource usage. Context-based traffic fuzzification is used to dynamically determine noise generation schemes and noise patterns based on the logical state of the system and IoT devices, as well as high-level factors such as applications and users associated with the current state of the system. These high-level factors are represented herein by the system state termed context.
[0059] Context-based traffic obfuscation enables multiple coordinated IoT devices to generate noisy transmissions. In contrast, traditional methods generate noise individually from individual IoT devices without coordination. Context-based traffic obfuscation combines multiple system components and elements, including peer-to-peer IoT devices, to generate noisy messages designed to confuse attackers. Figure 1 The newly introduced processes, such as the context manager 104 and traffic coordinator 106 shown, help generate artificial messages or noise transmissions that effectively confuse attackers, while minimizing the overall use of power, bandwidth, and other system resources.
[0060] Coordinate diagrams S1b, S2b, and S3b illustrate exemplary simplified message traffic patterns resulting from applying context-based traffic obfuscation to a system with three IoT devices. Those skilled in the art will readily recognize that the embodiments disclosed herein can be advantageously used in systems with more or fewer than three IoT devices without departing from the spirit and scope of the invention. When an IoT device is triggered and sends message 414, the traffic coordinator creates a pattern on the peer IoT device and the triggered IoT device consisting only of several randomly spaced noise transmissions 416, 418, and 420. These noise transmissions 416, 418, and 420 are used to confuse attackers while minimizing the amount of system resources consumed. Figure 3 The side-channel protection scheme shown is similar to Figure 4 A comparison with the context-based traffic obfuscation method shown demonstrates that the context-based traffic obfuscation technique provides equivalent protection but uses significantly fewer messages and correspondingly reduces the system resources consumed.
[0061] Figure 5 A flowchart is shown of an exemplary method 500 incorporating aspects of the disclosed embodiments, the exemplary method 500 being used to perform context-based message traffic obfuscation. The exemplary method 500 is applicable to computing devices such as the aforementioned computing device 102 to protect systems such as the exemplary system 100 from side-channel attacks by using the context-based traffic obfuscation techniques disclosed herein.
[0062] The exemplary method 500 begins by receiving input 502. The received input may include any of the aforementioned contextual attributes, such as system and environment attributes, user input, device information, and sensor information. These contextual attributes and system state can be used to determine whether a side-channel attack is possible at 504 and whether protective actions are effective.
[0063] A security context (506) is selected based on the aforementioned context attributes. The security context provides a representation of the system state and facilitates adjustments to subsequent actions to optimally manage system resources. In some embodiments, updating the security context (510) based on the selected security context may be advantageous when the selected security context differs from the currently active security context.
[0064] The security context and the received input can be advantageously used to determine whether 512 should implement a protection action. When no protection action is required, method 500 waits for other input. Embodiments of method 500 may optionally apply any of the above-described protection actions, including: completely suppressing the generation of message traffic, generating obfuscated noise message traffic, replaying recorded message traffic, and replaying predefined message traffic.
[0065] Flow control is determined at 516 to implement the desired protection action. Flow control includes a set of one or more traffic generation instructions that, when sent to an IoT device, cause the IoT device to generate or suppress message traffic or noise to support the desired protection action. To perform the flow control effectively and efficiently, an IoT device is selected at 518 based on the security context, context attributes, and device information. In some embodiments, device information such as device type, message or noise generation capabilities, power resources, and device location may be used to select one or more IoT devices that can effectively implement the desired protection action while minimizing system resource usage. Flow control is then sent at 520 to the selected IoT device.
[0066] Therefore, although the essential novel features of the invention applicable to exemplary embodiments thereof have been shown, described, and pointed out herein, it should be understood that those skilled in the art may make various omissions, substitutions, and changes to the form and details of the apparatus and methods, as well as the operation of the apparatus, without departing from the spirit and scope of the invention. Furthermore, it is explicitly desired that all combinations of elements that perform substantially the same function in substantially the same manner to achieve the same result are within the scope of the invention. Moreover, it should be recognized that structures and / or elements shown and / or described in connection with any form or embodiment of the disclosed invention may be incorporated as general design choices into any other form or embodiment disclosed, described, or suggested. Therefore, the invention is limited only to the scope set forth in the appended claims.
Claims
1. A device (102), characterized in that, The device (102) includes a processor (150) coupled to a memory (152); the processor (150) is configured to: Receive at least one context attribute, wherein the at least one context attribute includes one or more of the following: system and environment attributes (122), user input (124), device information (108), and sensing information (130). Based on at least one received context attribute, a security context (132) is selected, wherein the selected security context (132) includes one of the following: a privacy protection context, a hidden selected activity context, an intrusion mitigation context, and a risk-free context; Based on the selected security context, determine the protection action; Based on the determined protection action and the at least one context attribute, determine one or more flow control measures (134). Send one or more flow control measures (134) to one or more IoT devices (114). Wherein, one or more flow control measures (134) are used to cause the one or more IoT devices (114) to perform the protection action; The one or more flow control methods (134) are used to generate noise signals with random intervals from two or more IoT devices (138, 140).
2. The apparatus (102) according to claim 1, characterized in that, The processor (150) is used to select the privacy protection context when one or more people are in a protected area and the time is within a predefined time range.
3. The apparatus (102) according to claim 1, characterized in that, The processor (150) is used to select the hidden activity context when security personnel are on duty and the time is within a predefined patrol period.
4. The apparatus (102) according to claim 1, characterized in that, The protection actions include one or more of the following: completely suppressing the generation of message traffic, generating obfuscated noise message traffic, replaying recorded message traffic, and replaying predefined message traffic.
5. The apparatus (102) according to any one of claims 1-4, characterized in that, The one or more flow control methods (134) are used to cause the first IoT device (138) to generate a first noise flow pattern and to cause the second IoT device (140) to generate a second noise flow pattern; wherein the first noise flow pattern and the second noise flow pattern are time-shifted.
6. The apparatus (102) according to any one of claims 1-4, characterized in that, When the selected security context is the hidden selected activity context, the one or more flow control (134) is used to suppress message traffic in one or more of the one or more IoT devices (114).
7. The apparatus (102) according to any one of claims 1-4, characterized in that, The device information (108) includes power information, and the processor (150) is configured to configure one or more flow controls (134) based on the power information, wherein the power information includes information relating to the power capabilities of at least one of the one or more IoT devices (114).
8. The apparatus (102) according to any one of claims 1-4, characterized in that, The processor (150) is used to determine one or more flow control measures (134) based on network bandwidth.
9. The apparatus (102) according to any one of claims 1-4, characterized in that, The processor (150) is used to determine one or more flow control measures (134) based on a maximum reporting rate, wherein the maximum reporting rate is dynamically determined based on a minimum amount of noise traffic and the maximum transmission rate of the one or more IoT devices (114).
10. The apparatus (102) according to any one of claims 1-4, characterized in that, The flow control (134) includes one or more of the following: the data packet to be replayed, the script to be replayed, the random data packet size, the transmission frequency, the session length, the maximum data volume, and the stopping condition.
11. A method for obfuscating message traffic based on context (500), characterized in that, The method (500) includes: Receive (502) at least one context attribute, wherein the received at least one context attribute includes one or more of the following: system and environment attributes, user input, device information, and sensing information; Based on at least one received context attribute, a security context is selected (506), wherein the selected security context includes one of the following: a privacy protection context, a hidden selected activity context, an intrusion mitigation context, and a risk-free context; Based on the selected security context, determine the protection action (512); Based on the determined protection action and the at least one context attribute, determine (516) one or more flow control measures; Send one or more flow control statements (520) to one or more IoT devices. Wherein, one or more flow control measures are used to cause the one or more IoT devices to perform the protection action; The one or more flow control methods (134) are used to generate noise signals with random intervals from two or more IoT devices (138, 140).
12. A computer program product, characterized in that, The computer program product includes non-transitory computer program instructions that, when executed by a processor (150), cause the processor (150) to perform the method (500) according to claim 11.
Citation Information
Patent Citations
Methods and systems for thwarting side channel attacks
CN106415580A
Systems and methods for proactively enforcing a wireless free zone
US20080119130A1